HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of August 15, 2026.
-
How Anthropic plans to watermark Claude's AI-generated text
— Bleeping Computer
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across… -
Mission-Driven Security: Inside a Global Bank's Defense
— Dark Reading
In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the … -
Hackers arrested over €30M bank fraud exploiting service provider flaw
— Bleeping Computer
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at… -
Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI
— Dark Reading
Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Techn… -
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office
— Dark Reading
One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well. -
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
— Bleeping Computer
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnera… -
Who’s Tracking You? Use This New Service to Find Out
— Krebs on Security
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we… -
ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
— The Hacker News
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) c… -
ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Using Gemma4 with Ollama – Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th)
— SANS ISC
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware h… -
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
— The Hacker News
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impac…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (10832 in last 30 days).
Critical: 0 · High: 9 · Medium: 11 · Low: 0. View full dashboard →
-
CVE-2026-74250
— CVSS 6.3 (MEDIUM)
In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. -
CVE-2026-74247
— CVSS 4.2 (MEDIUM)
A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide⦠-
CVE-2026-74245
— CVSS 5.9 (MEDIUM)
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be interce⦠-
CVE-2026-74244
— CVSS 5.9 (MEDIUM)
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without⦠-
CVE-2026-74243
— CVSS 6.5 (MEDIUM)
A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the atta⦠-
CVE-2026-74242
— CVSS 5.3 (MEDIUM)
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive deta⦠-
CVE-2026-74241
— CVSS 4.8 (MEDIUM)
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username ⦠-
CVE-2026-74240
— CVSS 5.4 (MEDIUM)
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `⦠-
CVE-2026-73683
— CVSS 8.1 (HIGH)
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUse⦠-
CVE-2026-69414
— CVSS 7.8 (HIGH)
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update ⦠-
CVE-2026-74248
— CVSS 4.3 (MEDIUM)
OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octav⦠-
CVE-2026-73682
— CVSS 8.8 (HIGH)
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project t⦠-
CVE-2026-50523
— CVSS 7.8 (HIGH)
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. -
CVE-2026-73680
— CVSS 8.8 (HIGH)
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video ⦠-
CVE-2026-19910
— CVSS 7.5 (HIGH)
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX ⦠-
CVE-2026-19909
— CVSS 7.5 (HIGH)
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Auth⦠-
CVE-2026-19908
— CVSS 7.1 (HIGH)
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technol⦠-
CVE-2026-18554
— CVSS 7.5 (HIGH)
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. -
CVE-2026-18178
— CVSS 5.4 (MEDIUM)
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. -
CVE-2026-17227
— CVSS 5.4 (MEDIUM)
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · August 15, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment